You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

K3s部署Ansible AWX时ansible-galaxy安装集合报网络/解析错误

K3s部署AWX实例Ansible集合自动安装故障解决方案

问题概述

  • 基于K3s集群部署Ansible AWX实例后,启用Git项目同步关联的Ansible集合自动安装功能,功能运行异常
  • 项目通过collections/requirements.yml定义共7个待安装的Ansible集合:
    • community.general
    • community.mysql
    • community.docker
    • ansible.posix
    • community.vmware
    • community.zabbix
    • awx.awx
  • 安装流程会随机在下载某一个集合时触发报错,宿主机本地执行相同集合安装命令无异常;进入AWX容器手动执行安装命令时,报错会在*Network is unreachable(网络不可达)和Name or service not known(名称或服务未知)*两类错误间交替出现。

报错信息

作业标准错误输出

ERROR! Failed to download collection tar from 'server0': <urlopen error [Errno -2] Name or service not known> 

容器内手动执行安装的调试输出

在AWX容器内携带-vvv(verbose调试)、-c(忽略缓存)参数执行ansible-galaxy安装命令,返回如下信息:

bash-4.4$ ansible-galaxy collection install -r requirements.yml --collections-path /var/lib/awx/projects/.__awx_cache/_15__gitlab_ansible_awx_devops/stage/requirements_collections -vvv -c

ansible-galaxy [core 2.12.5.post0]
  config file = None
  configured module search path = ['/home/runner/.ansible/plugins/modules', '/usr/share/ansible/plugins/modules']
  ansible python module location = '/usr/local/lib/python3.8/site-packages/ansible
  ansible collection location = /home/runner/.ansible/collections:/usr/share/ansible/collections
  executable location = /usr/local/bin/ansible-galaxy
  python version = 3.8.12 (default, Sep 21 2021, 00:10:52) [GCC 8.5.0 20210514 (Red Hat 8.5.0-3)]
  jinja version = 2.10.3
  libyaml = True
No config file found; using defaults
Reading requirement file at '/var/lib/awx/projects/_15__gitlab_ansible_awx_devops/collections/requirements.yml'
Starting galaxy collection install process
Process install dependency map
Opened /home/runner/.ansible/galaxy_token
[WARNING]: Skipping Galaxy server https://galaxy.ansible.com/api/. Got an unexpected error when getting available versions of collection community.general: Unknown
error when attempting to call Galaxy at 'https://galaxy.ansible.com/api/v2/collections/community/general/': <urlopen error [Errno 101] Network is unreachable>
ERROR! Unknown error when attempting to call Galaxy at 'https://galaxy.ansible.com/api/v2/collections/community/general/': <urlopen error [Errno 101] Network is unreachable>

环境信息

  • 操作系统:Ubuntu 20.04
  • Ansible版本:ansible [core 2.12.5.post0]
  • AWX版本:AWX 21.1.0
  • K3s版本:k3s version v1.23.6+k3s1 (418c3fa8)

根因分析

该故障属于K3s在Ubuntu 20.04环境下的典型网络适配问题:

  1. Ubuntu 20.04默认使用systemd-resolved提供本地DNS解析服务,/etc/resolv.conf默认指向127.0.0.53的本地stub监听地址,K3s默认会将该文件作为CoreDNS的上游解析配置来源,但Pod网络无法直接访问宿主机的本地回环DNS服务,导致随机出现域名解析失败。
  2. Ubuntu默认启用的ufw防火墙默认未放通cni网桥的转发流量,会随机拦截Pod网段访问公网的转发请求,导致间歇性网络不可达。

修复步骤

  1. 修正K3s DNS配置
    • 停止K3s服务:systemctl stop k3s
    • 编辑K3s服务配置文件/etc/systemd/system/k3s.service,在ExecStart行的启动参数末尾追加--resolv-conf /run/systemd/resolve/resolv.conf,指定K3s直接使用systemd-resolved生成的、包含真实上游DNS地址的配置文件,跳过本地stub解析。
    • 重载系统服务配置并重启K3s:
      systemctl daemon-reload
      systemctl start k3s
      
  2. 放通Pod网络转发规则
    • 调整ufw规则,允许cni网桥的进出流量,开启路由转发默认允许策略:
      ufw allow in on cni0
      ufw allow out on cni0
      ufw default allow routed
      
    • 配置iptables FORWARD链默认策略为接受,避免规则拦截:iptables -P FORWARD ACCEPT
  3. 连通性验证
    • 查询AWX命名空间下的任务Pod名称:kubectl get pods -n awx | grep task
    • 进入任务Pod验证公网访问和DNS解析能力:
      kubectl exec -it <替换为实际的awx-task Pod名称> -n awx -- bash
      curl -I https://galaxy.ansible.com
      nslookup galaxy.ansible.com
      
    • 确认返回正常无超时、解析结果正确后,手动触发一次项目同步,验证集合自动安装功能是否恢复。
  4. 兜底优化方案
    如果上述配置完成后仍存在偶发安装失败,可直接构建预安装所有依赖集合的自定义AWX执行环境镜像,跳过项目同步时的在线安装步骤:
    • 编写Dockerfile,在基础执行环境镜像中提前安装所需集合:
      FROM quay.io/ansible/awx-ee:latest
      COPY collections/requirements.yml /tmp/requirements.yml
      RUN ansible-galaxy collection install -r /tmp/requirements.yml
      
    • 构建镜像并推送到集群可访问的镜像仓库,在AWX的执行环境配置中添加该自定义镜像,关联到对应项目使用即可。

内容的提问来源于stack exchange,提问作者Coorchak

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.29 12:15:27